Privacy notice
Last reviewed: 7 September 2026
The short version: we use our own traffic counters, not Google Analytics, advertising networks, tracking pixels, or session recording. Nobody buys data from us. You can read every deal without an account; we still receive the ordinary request information every website receives, including your network address, and the exact handling is described below.
What we do not do
- No third-party analytics. No Google Analytics, Meta pixel, heatmaps, ad-tech identifiers, or session recording. Our first-party counters are described below. There is no third-party JavaScript on ordinary reading pages; Turnstile is the limited exception.
- No advertising profiles. We do not build one, buy one, or sell into one.
- No hotlinked merchant images. Deal images are served from our own domain, so browsing a deal page does not announce your visit to the merchant.
- No email marketing. We do not have a newsletter. Your address is used to sign you in and to reach you about your own account.
First-party traffic measurement
We count page views so we can tell whether readers or crawlers are using the site, which public pages are useful, and whether people arrived from search, social, an AI assistant, another website, or directly. This runs on our server: there is no analytics script or analytics cookie in your browser.
For a counted public page request, we retain:
- the page path, with the query string removed;
- the client IP address and a separate keyed digest used for unique counts;
- country, region, and city supplied by the Cloudflare edge, when available;
- a coarse device/crawler class and recognised browser or crawler name; and
- a coarse arrival channel and referring hostname.
We do not store search terms, query strings, full referrer URLs, or the raw User-Agent header in these traffic tables. Requests are buffered in memory and folded into daily aggregates rather than stored as a row-by-row browsing log. The five-minute “online now” view is memory-only and disappears when the process restarts.
Cookies we set
All three are first-party, all are SameSite=Lax, and over HTTPS all carry the
__Host- prefix, which pins them to this exact domain so a subdomain cannot set or
read them. None of them are advertising cookies, which is why you are not being shown a consent
banner asking permission to track you.
jb_session — Keeps you signed in.
Set only after you sign in. What we store is a SHA-256 digest of the cookie value, never the value itself, so a copy of our database cannot be replayed as your login.
Lifetime: 30 days, extended while you keep using the site.
jb_device — Lets one browser vote once per deal.
Set on your first page view whether or not you have an account. It identifies a browser, not a person. The device row holds creation and last-seen times; votes and abuse limits can be associated with that device identity, but it has no name, address, or profile.
Lifetime: 1 year.
jb_csrf — Blocks other websites from acting as you.
The one cookie readable by JavaScript, because the protection works by our own pages echoing it back in a header. It is a random value with no meaning attached to it.
Lifetime: 30 days.
Browser storage that is not a cookie
-
jb-themeandjb-accentremember the light/dark and colour choices on this device until you clear site storage. They are not sent with requests. -
jumpbump:speed-tabbriefly records whether you moved from Flash or Bomb so the next page can animate in the correct direction. It is removed as soon as that page reads it and otherwise disappears when the browser tab closes. - The restricted operator console remembers its list/card view in local storage. Public readers do not use that setting.
What we store if you make an account
An account is optional. It exists so you can vote and comment under a name. We store:
- Your username and email address. The username is public on your comments. The email is not shown to anyone.
- A hash of your password, produced with scrypt and a random per-account salt. We cannot read your password, recover it, or tell you what it was, because we never store it.
- Your sign-in times and the browser string of each active session, so you can tell your own sessions apart.
- Your votes, comments, and any reports you file. Votes are stored against your account and your browser so one person cannot vote repeatedly.
Messages and correspondence
When you contact us, we retain your sender address, message and any attachments needed to handle the correspondence. Authorized administrators use a private mailbox to read and answer it. Outgoing messages and attachments are processed by our mail provider, Brevo; incoming email forwarding uses Cloudflare and our configured external mailbox. Remote email images and active HTML are not automatically loaded.
Large attachments may be shared with an explicitly generated download link that expires after seven days. Anyone holding that link can download the file during that period. We retain correspondence until reviewed and deleted or until a deletion request is handled; saved attachments are also included in encrypted backups.
Your IP address
The first-party traffic tables retain the address for the 180-day period below so the operator can distinguish real readers from crawler or abuse traffic by day and page. It is not linked to your account. Rate limits use a separate keyed one-way digest instead of the raw address; IPv6 addresses are first truncated to their /64 network for that digest.
Caddy also writes an ordinary security/access log containing the address, request method, path, response status, duration, response size, User-Agent, and country. Cookies, authorisation headers, CSRF tokens, query strings, and Cloudflare's stable device tag are removed before logging. The log rotates daily and 14 rotations are retained.
Ask AI deal assistant
Ask AI is optional and works without an account. When you send a message, we send your question, a bounded amount of recent conversation, and relevant public deal information to our configured AI gateway and model provider. No AI request is made merely because you browse a page.
The website does not save chat transcripts in its databases, cookies, or browser storage. The chat stays in your current tab's memory while you navigate between public JumpBump pages. Refreshing the page, closing the tab, or choosing New chat clears it; a new tab starts a separate conversation. AI gateways and providers may handle or retain submitted text under their own policies, so do not send passwords, payment details, or other personal or sensitive information.
The assistant can search and read public JumpBump deals only. It cannot access member records, edit the website, make purchases, or browse arbitrary external sites. We keep limited request counters against a keyed network-address digest and site-wide totals to control abuse and AI usage. Replies can contain mistakes, and advertised prices or availability may have changed.
Infrastructure and Turnstile
Public traffic passes through Cloudflare for DNS, HTTPS protection, and the private tunnel to our Oracle-hosted server. Cloudflare therefore processes connection and request metadata, including your network address, for every visit. Oracle hosts the application and operational data on the server we administer.
Registration is protected by Cloudflare Turnstile, a bot challenge. It runs only on the sign-up form and on sign-in after repeated failures, never on the pages you browse. Turnstile adds challenge and browser signals to the ordinary edge processing described above; Cloudflare's handling is governed by Cloudflare's privacy policy. We chose it over a Google reCAPTCHA specifically because it is not tied to an advertising business.
Outbound links to merchants
When you tap through to a deal you leave our site and land on the merchant's, sometimes via an affiliate network. From that moment their cookies and their privacy policy apply, not ours, and the network may record that the click came from us in order to attribute a commission. We do not receive your name, your order, or your payment details — only, at most, an aggregate count of clicks and sales. See the affiliate disclosure for how that relationship works.
How long we keep things
- Sessions: deleted at expiry, or immediately when you sign out.
- Rate-limit counters: windows of up to 24 hours, with older records discarded during routine cleanup.
- First-party traffic aggregates: 180 days, then purged automatically.
- Caddy access logs: daily rotation with 14 rotations retained.
- Your account, comments and votes: until you ask us to delete them.
- Backups: encrypted, and rotated out after 14 days. A deletion is reflected in backups once that window passes.
Deleting your data
Email [email protected] from the address on the account and we will delete the account, its sessions, and its votes. Comments can be deleted with it or detached from your name if a discussion would otherwise become unreadable — say which you prefer. You can also ask for a copy of what we hold, which is the list above and rarely a surprise.
Children
This site is not directed at children and we do not knowingly create accounts for anyone under 13. If you believe we have, write to us and it will be removed.
Changes
If this notice changes materially, the reviewed date above changes with it. We do not backdate revisions.